Threat Database Backdoors Backdoor.Win32.Agent.ago

Backdoor.Win32.Agent.ago

By ZulaZuza in Backdoors

Backdoor.Win32.Agent.ago is a backdoor trojan infection that runs in the background and opens a backdoor in your PC and enables the attacker to issue commands remotely to monitor the compromised machine. Backdoor.Win32.Agent.ago is able to steal your personal data like credit card numbers. Backdoor.Win32.Agent.ago will download files to the computer without victim's authorization, which will lead to security danger. Backdoor.Win32.Agent.ago can even enable a hacker to gain remote access to the affected computer.

File System Details

Backdoor.Win32.Agent.ago may create the following file(s):
# File Name Detections
1. %System%\_sv_.exe
2. %System%\drivers\_sv_.sy [file and pathname of the sample #1]

Registry Details

Backdoor.Win32.Agent.ago may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfscore\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\_sv_
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfscore
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\_sv_
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\_sv_

Trending

Most Viewed

Loading...